New seats:node-environment (no verbs) and node-login-shell (verb execute). A module declaring login-shell is refused (ADR 0204).
New manifest fields:
environment: variables and path entries placed at the start or end;
shell: code for zsh/bash/fish in a first/normal/last slot.
Both are parsed strictly, and a value carrying $ (other than ${machine:…}), a quote, a backslash or a line break is refused.
Composition fills, in the claiming holder's file contents:
${environment:posix}: exports, plus PATH entries added only if missing, so sourcing twice changes nothing;
${environment:systemd}: environment.d syntax;
${shell:<shell>:<slot>}: filled last and never re-scanned, so contributed ${…} code passes through byte for byte.
Refused:
a variable set by two modules on one node;
a placeholder in a module that does not claim the seat (at the catalogue check and at composition);
an unknown placeholder key.
Tests: internal/catalogue/environment_into_test.go. The POSIX rendering is sourced twice by sh, and the systemd rendering is run through the real environment-d generator where one is installed. The full suite passes with Postgres and NATS, except TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves, which already fails on main. module check over the catalogue branch of the same name passes all 73 manifests.
hq to-be 41 WP2.
- **New seats:** `node-environment` (no verbs) and `node-login-shell` (verb `execute`). A module declaring `login-shell` is refused (ADR 0204).
- **New manifest fields:**
- `environment`: `variables` and `path` entries placed at the `start` or `end`;
- `shell`: code for zsh/bash/fish in a `first`/`normal`/`last` slot.
Both are parsed strictly, and a value carrying `$` (other than `${machine:…}`), a quote, a backslash or a line break is refused.
- **Composition fills, in the claiming holder's file contents:**
- `${environment:posix}`: exports, plus PATH entries added only if missing, so sourcing twice changes nothing;
- `${environment:systemd}`: environment.d syntax;
- `${shell:<shell>:<slot>}`: filled last and never re-scanned, so contributed `${…}` code passes through byte for byte.
- **Refused:**
- a variable set by two modules on one node;
- a placeholder in a module that does not claim the seat (at the catalogue check and at composition);
- an unknown placeholder key.
Tests: `internal/catalogue/environment_into_test.go`. The POSIX rendering is sourced twice by `sh`, and the systemd rendering is run through the real environment-d generator where one is installed. The full suite passes with Postgres and NATS, except `TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves`, which already fails on main. `module check` over the catalogue branch of the same name passes all 73 manifests.
node-environment says which module writes the account's environment; node-login-shell
replaces the module-declared login-shell, so a second shell claims it rather than
declaring a rival, and execute is the mesh's contract. login-shell is refused as a
module's seat name. Seeded into a live store by the existing additive seeding.
A module contributes environment variables, PATH entries and shell code in named slots;
the holder of the matching seat places them with ${environment:posix|systemd} and
${shell:<shell>:<slot>}. Rendered in module order with a naming line per contribution,
PATH entries added only when missing, machine facts resolved first. A variable two
modules set, or a placeholder outside its seat's holder, is refused at parse (the
catalogue check) and at composition. Filled after every other placeholder pass, so no
scanner ever reads a shell's own ${...}.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
hq to-be 41 WP2.
New seats:
node-environment(no verbs) andnode-login-shell(verbexecute). A module declaringlogin-shellis refused (ADR 0204).New manifest fields:
environment:variablesandpathentries placed at thestartorend;shell: code for zsh/bash/fish in afirst/normal/lastslot.Both are parsed strictly, and a value carrying
$(other than${machine:…}), a quote, a backslash or a line break is refused.Composition fills, in the claiming holder's file contents:
${environment:posix}: exports, plus PATH entries added only if missing, so sourcing twice changes nothing;${environment:systemd}: environment.d syntax;${shell:<shell>:<slot>}: filled last and never re-scanned, so contributed${…}code passes through byte for byte.Refused:
Tests:
internal/catalogue/environment_into_test.go. The POSIX rendering is sourced twice bysh, and the systemd rendering is run through the real environment-d generator where one is installed. The full suite passes with Postgres and NATS, exceptTestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves, which already fails on main.module checkover the catalogue branch of the same name passes all 73 manifests.A module contributes environment variables, PATH entries and shell code in named slots; the holder of the matching seat places them with ${environment:posix|systemd} and ${shell:<shell>:<slot>}. Rendered in module order with a naming line per contribution, PATH entries added only when missing, machine facts resolved first. A variable two modules set, or a placeholder outside its seat's holder, is refused at parse (the catalogue check) and at composition. Filled after every other placeholder pass, so no scanner ever reads a shell's own ${...}.